Case #002: Trojan Supply Chain Attack

Target: SolarWinds (and ~18,000 downstream customers)

Date: December 2020

Threat Actor: APT29 / Cosy Bear / Nobelium (Russian SVR)

Attack Vector: Software Supply Chain Compromise (Code Build Injection)

Impact: Estimated $90m+, corporate damages across victim networks in the billions

The Crack

Implied trust in digital vendor signatures

Organisations rely on digital signatures to confirm code is safe. The attackers didn’t need to hack over 18,000 targets one-by-one, they sneaked a backdoor into a commonly used application during a routine update and had the vendor digitally sign it for them

The Execution

  • Silent Foothold: Attackers had compromised SolarWinds’ internal network months prior (back in 2019) quietly observing of how their monitoring tool (Orion) was built and shipped.
  • Build Tampering: They injected a custom tool into the build process. Every time SolarWinds built an update, the tool swapped out a legitmate code file out for a backdoored version before it was compiled.
  • Legitmate Sign-Off: SolarWinds’ automated system cryptography signed the software package with their corporate certificate marking the malicious release as trusted and authentic.
  • Trojan Distribution: SolarWinds pushed the signed update to ~18,000 customers which once installed opened a back door into victim’s networks without raising any flags on endpoint tools.

The Blast Radius

  • Global Espionage: Russian Intelligence gained backdoor access to U.S. federal agencies; Department of Homeland Security (DHS), Department of Justice (DOJ), Treasury and other top-tier tech giants.
  • Nine Months of Silence: The attackers lived, undetected within the SolarWinds networks for over 9 months
  • Total Infrastructure Rebuild: Many victims had to tear down and completely rebuild environments as standard cleanup methods couldn’t guarentee the attackers had been removed.

The Hardening Plan

  • Enforce Zero-Trust for Apps: Treat vendor software tools as high-risk assets. Network monitoring tools should never have unrestricted, direct outbound access to the Internet.
  • Integrity Checks on Build Pipelines: Development teams but use deterministic, reproducable builds and real-time file monitoring to ensure source code matches the compiled binaries line-by-line.
  • Monitor Egress Traffic: Watch for unusual outbound DNS queries or unknown external IP connections, whether or not you believe its coming from a trusted application or not.

Scroll to Top